Severity
2.1LOW
EPSS
0.1%
top 75.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 28
Latest updateJan 13

Description

IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not prevent caching of documents retrieved in SSL sessions, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

NVDibm/tivoli_directory_server6 versions+5

Patches

🔴Vulnerability Details

5
OSV
libxmltok vulnerabilities2025-01-13
GHSA
OpenNMS Horizon vulnerable to XSS2022-05-24
GHSA
GHSA-ww3r-g52r-m6j3: IBM Tivoli Security Directory Server 62022-05-17
GHSA
Cross-Site Request Forgery in OpenNMS Horizon2021-05-25
CVEList
CVE-2015-2019: IBM Tivoli Security Directory Server 62015-06-28

💥Exploits & PoCs

6
Exploit-DB
Seagate Central Storage 2015.0916 - Unauthenticated Remote Command Execution (Metasploit)2023-05-25
Exploit-DB
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection2020-11-19
Exploit-DB
Microsoft Windows Kernel - Information Disclosure2020-01-27
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass (MS15-014)2019-10-29
Exploit-DB
SaLICru -SLC-20-cube3(5) - HTML Injection2019-04-08

📋Vendor Advisories

2
Microsoft
Skype for Business Remote Code Execution Vulnerability2023-10-10
Red Hat
struts: XSS vulnerability when JSP files are exposed to be accessed directly2015-08-26

🕵️Threat Intelligence

4
Trendmicro
Backdoor-Variante infiziert Word-Dokumente und PDFs2019-08-26
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities2019-08-22
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities2019-08-22
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities2019-08-22

💬Community

2
HackerOne
Apache HTTP [2.4.17-2.4.38] Local Root Privilege Escalation2019-09-11
Bugzilla
CVE-2019-12815 proftpd: file copy vulnerability in mod_copy allows for remote code execution2019-07-23
CVE-2015-2019 (LOW CVSS 2.1) | IBM Tivoli Security Directory Serve | cvebase.io